N Gauge Society Ltd
The Data Protection law – Guidance for Members
Privacy Notice Overview
What is this document about?
A new data protection law called the General Data Protection Regulation (GDPR) took effect from 25th May 2018. Under the new law the N Gauge Society Ltd (referred to below as NGS) must provide its members with information about what personal information relating to them the NGS holds and what it does with that information. This document describes how this affects the NGS and you as members of the NGS, in a question and answer format. It should be used as an introduction to a formal document, the Privacy Notice, to be found here: Privacy Notice (Formal)
Why does the NGS have to bother with this?
The new law applies across the whole of the European Union (and was incorporated into UK law prior to Brexit). Unlike the old legislation it replaces, all organisations that hold personal information must register and comply with the new law. This includes the NGS as we hold personal information of our members.
What do you mean by ‘personal information’?
The new law defines this as any information that can be used to identify an individual, but in the case of the NGS we only hold the names and addresses of our members and, where they have been provided, their telephone numbers and email addresses. Collectively these are known as ‘contact information’.
Why does the NGS hold our contact information?
The NGS maintains a membership list of current and lapsed members in order to provide the members with the services and products they join the society to benefit from. We only collect contact information from our members or individuals applying for membership.
Does the new law actually change anything then?
It does not change the data the NGS holds about you, or how it is used. The NGS is obligated to review and document its methods and procedures for handling personal information and to demonstrate that it is complying with the new law. As an individual, you have more rights over what we can do with the personal data that we hold on your behalf.
How does the NGS use our contact information?
The contact information is used to enable members to join, renew and change their membership. We call this ‘membership services’.
It is also used to post out the bimonthly Journal and Newsletter to the members and, for example, to contact members to remind them if their membership has expired. We call this ‘membership contact’.
Finally, it is used to process orders raised by members with the NGS shop. This ensures that only genuine members order from the shop, that the goods are delivered to the correct address and that we can contact the member if there are any questions or issues with their orders. We call this ‘member order processing’.
Do you give or sell our contact information to anyone else?
We do not sell your information to anyone else. Under the new law this would be illegal anyway without getting your consent. The only outside organisation we give the contact information to is those that print and post the Journal and Newsletter, so that they know where to send the publications.
Do we have to give consent – sign or tick something?
No, unlike many large, commercial organisations that may ask your permission, the NGS has gone down a different route, as is allowed by the new law. The NGS is a not-for-profit society where membership is voluntary and specifically to access the benefits that the NGS offers. Therefore, the NGS has a legitimate interest to hold and use your contact information in order to provide you with these benefits and so does not need your permission. If you do not want us to hold your contact information, then you can leave the NGS and instruct us to delete your contact information.
Does that mean I don’t have any rights over my contact information held by the NGS?
Not at all. The new law lays down the rights that individuals have and the NGS will abide by these where they are applicable. You do have the right to ask us to delete your contact information, but if you do we can no longer provide you with the services and products you joined for and so there will be no benefit in remaining in the NGS. You also have rights to see, change, restrict, object and be kept informed about your contact information.
How does the NGS look after my contact information?
The information is only available to those officers of the society that need to use it to fulfil their duties (e.g. Membership Secretary, Shop Manager).
Depending on which system is used, the information is password protected and/or encrypted. We don’t store or send the contact information outside of the UK, so it is always protected by the current and new data protection laws.
We have rules about removing old data belonging to former members. This is set up in such a way that should a member forget to renew their membership on the due date, their contact information is retained in a separate list for up to six months to help the membership to be reinstated with least inconvenience to the member. If you choose to leave the NGS it is better therefore that you tell us rather than let membership lapse so that we can immediately delete your contact information.
Where can I find out more?
This document provides an overview to a more formal document called the ‘Privacy Notice’ which, under the new law, must be provided to each member. The Privacy Notice gives more detail than the above and who to contact for more information: Privacy Notice (Formal)